Bitget CEO Gracy Chen publicly criticized decentralized protocol THORChain for declining to block addresses associated with a recent security breach. The incident occurred on September 24, resulting in an estimated loss of $387.5 million across Ethereum, XRP Ledger, Zcash, and TRON networks. On September 26, Chen formally requested that THORChain intervene to stop the flow of stolen funds through its cross-chain infrastructure. THORChain refused the request, citing its permissionless design principles as the basis for non-intervention.
Chen highlighted a contradiction in THORChain’s stance by referencing the protocol’s response to its own exploit in May 2026. During that earlier incident, attackers drained approximately $10.7 million from THORChain vaults, prompting the team to halt operations entirely for roughly 39 days to address vulnerabilities. Chen argued that if THORChain could suspend its network when its own assets were at risk, citing decentralization to avoid blocking addresses linked to a larger theft appeared inconsistent. Meanwhile, stolen funds continued moving through the protocol, including a tracked swap of approximately $6.3 million in ETH for around 75.2 BTC.
The dispute between Bitget and THORChain underscores the growing tension between decentralized protocol ideals and practical compliance expectations following major security incidents. By refusing to block specific addresses while having previously halted its own network for nearly six weeks, THORChain faces scrutiny over whether its commitment to permissionless operation is absolute or selectively applied. This inconsistency challenges the narrative that such protocols are purely neutral infrastructure immune to intervention when illicit activities occur. The episode serves as a significant case study for regulators examining how DeFi entities handle accountability and fund recovery efforts.
From a market structure perspective, this incident provides concrete evidence for global regulators sharpening their focus on cross-chain protocols' roles in facilitating illicit fund flows. Chen’s public criticism adds data points that authorities can reference when constructing frameworks for DeFi accountability. If protocols demonstrate selective intervention capabilities, it becomes increasingly difficult to argue they lack the technical capacity or operational willingness to comply with broader regulatory standards. Investors and institutions should watch how this debate influences future policy decisions regarding custody, monitoring obligations, and the legal status of decentralized exchanges.


